Isolated-vm security fixes for sandbox escape flaw
Security Patch Release
Summary
Hide ▲
Show ▼
Security fixes for isolated-vm now close a sandbox escape flaw in affected releases, reducing the risk of host memory corruption and potential host RCE. The patch covers all versions before and including 7.0.0 and ships in 6.2.0 and 7.0.1. The issue is tracked as GHSA-864f-rcv7-6rh4.
Related Happenings
Linux kernel stable maintainers security patch release for CVE-2026-53359
Security Patch Release
H score41
First: 06.07.2026 20:37
Last: 06.07.2026 20:37
Sources 1
About this happening:
The Linux kernel shipped stable fixes for CVE-2026-53359, closing a KVM use-after-free on x86 hosts with nested virtualization. The fix reached 7.1.3, 6.18.3...
Linux kernel stable maintainers security patch release for CVE-2026-53359
Security Patch ReleaseAbout this happening: The Linux kernel shipped stable fixes for CVE-2026-53359, closing a KVM use-after-free on x86 hosts with nested virtualization. The fix reached 7.1.3, 6.18.3...
Linux kernel Dirty Frag patch release (CVE-2026-43284, CVE-2026-43500)
Security Patch Release
H score32
First: 11.05.2026 17:30
Last: 11.05.2026 17:30
Sources 1
About this happening:
Major Linux distributions are rolling out fixes for Dirty Frag, the Linux kernel patch release that covers CVE-2026-43284 and CVE-2026-43500. The update matter...
Linux kernel Dirty Frag patch release (CVE-2026-43284, CVE-2026-43500)
Security Patch ReleaseAbout this happening: Major Linux distributions are rolling out fixes for Dirty Frag, the Linux kernel patch release that covers CVE-2026-43284 and CVE-2026-43500. The update matter...
Linux kernel security update for Copy Fail (CVE-2026-31431)
Security Patch Release
H score39
First: 30.04.2026 16:54
Last: 30.04.2026 16:54
Sources 1
About this happening:
Linux kernel maintainers have fixed CVE-2026-31431 and are rolling out updates to close a local privilege escalation flaw that lets an unprivileged attacker gain roo...
Linux kernel security update for Copy Fail (CVE-2026-31431)
Security Patch ReleaseAbout this happening: Linux kernel maintainers have fixed CVE-2026-31431 and are rolling out updates to close a local privilege escalation flaw that lets an unprivileged attacker gain roo...
Vm2 maintainers security patch release for CVE-2026-22709
Security Patch Release
H score45
First: 28.01.2026 16:01
Last: 28.01.2026 16:01
Sources 1
About this happening:
vm2 maintainers released a fix for CVE-2026-22709 in vm2 3.10.2 and directed users to upgrade to 3.10.3, reducing the risk of sandbox escape and arbitrary co...
Vm2 maintainers security patch release for CVE-2026-22709
Security Patch ReleaseAbout this happening: vm2 maintainers released a fix for CVE-2026-22709 in vm2 3.10.2 and directed users to upgrade to 3.10.3, reducing the risk of sandbox escape and arbitrary co...
Timeline
-
20.08.2026 16:48 2 articles · 2h ago
isolated-vm patches GHSA-864f-rcv7-6rh4 in 6.2.0 and 7.0.1
Mitigation Patch UpdateEndor Labs disclosed a critical flaw in isolated-vm that can let code running inside the sandbox escape to the host and corrupt memory in the host process, and the issue was patched in versions 6.2.0 and 7.0.1 released earlier this month. The vulnerability, tracked as GHSA-864f-rcv7-6rh4, affects all versions of the library before and including 7.0.0 and can lead to SIGSEGV crashes or a guest-to-host sandbox escape.
Show sources
- Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE — thehackernews.com — 20.08.2026 16:48
- Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE — thehackernews.com — 20.08.2026 16:48